I was at a wedding the other weekend.
Somewhere between the speeches and the dancing, I got talking to a man who runs a manufacturing business. He asked what I did for a living, and when I told him, something in his face changed. He’d been hit by ransomware.
Then, he asked me the question I knew he would.
“So how do I stop it happening again? Is insurance the only thing that actually works?”
He wasn’t being naive. He’d been attacked, survived it, and come out the other side convinced, like so many others, that insurance was the best protection available. Everything else, as far as he could tell, was something you bought and hoped about.
So, I asked him about the incident itself.
He was fluent on the attack. How they got in, what they did once they were inside, how long it took to spot them, what it cost. He’d clearly told that story many times.
Then, I asked what came back first, and who decided.
Those parts he wasn’t clear on.
I’ve thought about it ever since, because it isn’t unusual. It’s our whole industry in miniature. We’ve become articulate about attacks and stayed illiterate about recovery.
Insurance does real work, and I changed my mind on several things when I looked at it properly last month. But it transfers some of the financial impact. It cannot tell you what must come back first, whether you can recover it cleanly, or who has authority to make those calls under pressure.
He had protection against some of the loss. He had no proof that the business could recover. Both matter, but only one of them gets you trading again.
There’s now a name for the operating model that closes that gap – resilience operations, or ResOps, meaning the discipline of treating recovery as a continuous, business-owned capability rather than an IT plan on a shelf.
We didn’t get worse; the bar just moved
New research from IDC, sponsored by Commvault, describes the first quarter of this year as a sea change: the window between compromise and full breach has compressed past the point where conventional response cycles keep up. Across their survey of 539 North American organisations, 84.5% had been attacked in the previous 12 months.
But the finding I can’t stop thinking about isn’t about attackers at all. IDC is explicit that the weakness in most organisations sits in the gaps between functions rather than inside any one of them. IT, cybersecurity and the business have approached resilience from separate corners, with no shared operating model, no common language, and no agreed recovery strategy. Finding and exploiting those seams used to require a capable adversary. It doesn’t any more.
So, we didn’t get worse. The bar just moved, and our structure stayed where it was.
Organisations know this about themselves. In IDC’s survey, 98.4% of respondents said collaboration between the teams responsible for IT security needs to improve. When almost everyone agrees, you’re not looking at an opinion. You’re looking at people describing a condition they live in.
So, ask yourself who is actually in the room that decides how your organisation survives. Is it the people who know which processes generate revenue, which customers can’t be kept waiting, and which obligations don’t pause for an incident? In most organisations it isn’t, and that’s a design flaw rather than a failure of goodwill. Better coordination alone won’t close it. The operating model has to change.
You cannot recover to a target you never set
The man at the wedding had a version of this problem, and it has a name.
IDC calls it the minimum viable business (MVB), the smallest complete set of functions, processes, systems and data you need to serve customers and generate revenue. It isn’t full restoration. It’s the minimum you need to still be a business, and it has to come back before anything else so you can keep trading while the longer recovery runs behind it.
More than half of organisations, 57.7%, haven’t fully defined theirs.
The qualitative findings show how hard it is to do honestly. In some organisations the claimed MVB covered as much as 80% of the application catalogue, which is another way of saying no prioritisation happened at all. And not one resilience leader interviewed could put a firm SLA against MVB recovery.
I read that as an honest starting point rather than a failure. In my experience the exercise always takes longer than anyone budgets for, and the argument it provokes is the whole point. It forces business and technology leaders to agree, in advance and in writing, on what actually matters, before an incident decides for them. IDC suggests scoping it across revenue criticality, regulatory obligations, customer experience thresholds, employee productivity, and the minimum security posture you need to avoid a second breach mid-recovery.
That last point is crucial. Recovery is the moment you’re most exposed, and most organisations plan for it as though it’s the moment the danger ends.
The proof gap
Finding is not proving. Until you’ve exercised a plan under realistic conditions, all you have is an intention.
Three findings in IDC’s report show how exposed organisations are:
- More than 59% have limited or no cleanroom capability, meaning they’d recover straight into production with nowhere isolated to scan and validate first. IDC likens it to surgeons operating without sterilising their instruments.
- More than 64% still determine recovery points manually. When someone is hand-picking which copy of your data to trust, at pace, under pressure, the decision that governs whether you recover cleanly is being made by an exhausted human at 3am. Invariably mistakes multiply.
- Only 26.9% work from an integrated platform with unified policy management, so most organisations are reconciling fragmented tooling at the moment they can least afford to.
Every one of those is the difference between holding a capability and being able to demonstrate it works. Look at your own environment and ask which of the three you could evidence this afternoon, without a project. As I’ve said before, you can have an annual plan, a signed policy and a clean audit finding, and still not know whether you can bring the business back. Compliance is not security.
Regular readers of mine will recognise what this looks like from my series on car safety. An MOT proves the car was roadworthy on the day it was tested. It doesn’t prove it’s safe today. Resilience works the same way. An annual exercise proves what happened on the day of the exercise. What matters is whether the crumple zone works when you actually hit something.
Most organisations have the certificate. Far fewer have tested the crumple zone.
One sector has already been made to prove it. Under the FCA’s PS21/3 and the PRA’s SS1/21, financial services firms had to identify their important business services, set impact tolerances for the maximum tolerable disruption to each, map what underpins them, and, by 31 March 2025, demonstrate through scenario testing that they can stay within those tolerances.
Essentially, this means that important business services are the minimum viable business. Impact tolerances are the recovery target no one in IDC’s interviews could name. Scenario testing is the evidence. British regulators mandated this operating model five years ago without calling it that. Unfortunately, everyone else has been left to volunteer.
What ResOps changes
IDC defines resilience operations as a continuous, operational discipline integrating cyber preparedness, infrastructure, data protection and disaster recovery with the delivery requirements of the business. Two words stood out to me. The first, continuous, which rules out the annual project and the document that gets refreshed for audit. The second, business, meaning success is measured by whether you can serve customers and generate revenue, not by RTOs alone.
ResOps isn’t a product, and no vendor sells one. It’s an operating discipline where governance gives it authority, and technical capability makes recovery executable. Which is why organisations with excellent tooling still can’t answer the question I asked at that wedding. The tooling was never the missing part.
And this is the part I’m stressing. The problem was never simply a shortage of persuasion. It was ownership. Advocacy rarely survives a budget cycle. Structure does.
IDC maps ResOps maturity across four stages: Reactive, Aware, Coordinated and Resilient. The important transition is from Aware to Coordinated, because that’s where informal cooperation becomes funded, governed and accountable. It’s also where most organisations stall. And a maturity score is only useful if it leads to evidence. The moment “we’re Stage 3” becomes the answer, you’ve recreated the exact problem the discipline exists to solve.
Where to start
If you’re a CISO, I’d start by finding out where you are. Take this assessment which is built on IDC’s maturity framework: https://resilience.commvault.com/
Use it as a diagnostic, as it gives you something concrete to take into the conversation that has to happen next.
Then, get the right people in a room, including the ones who own the revenue and not only the ones who own the servers, and answer three questions.
- What must come back first?
- Within what tolerance?
- And who decides, at some ungodly hour, when the answer is contested?
Because knowing your maturity is useful but agreeing what the business actually needs to survive is what makes it actionable.
If you’re not an enterprise with governing groups and a chartered function, this scales down further than you’d think. The smallest useful version is a single page: your top five revenue-critical processes, what each one actually depends on, and a named person who owns the call. I’d back that page against most of the resilience documentation I’ve read.
Now I want to hear from you…
We’ve spent decades getting very good at documenting resilience. The next era belongs to the organisations that can demonstrate it, on demand, with evidence. Starting with what comes back first, and who decides.
That’s why I want to know your view on this. If recovery has to be proven, rather than simply planned, what needs to change first? Join me on LinkedIn and let me know there – it’s where this conversation is happening.
In the spirit of full disclosure: I’ve received compensation for promoting this thought leadership blog. I only align myself with organisations and solutions I believe in, those that genuinely address the challenges I research and write about. Commvault is one of them.
